InnovateXP Limited - AI CRM and Event Management Solutions Hong Kong
InnovateXP Limited

03 / 15·PDPO, cross-border data, and private AI

Sending Hong Kong company data to the mainland or overseas

Direct answerAs of this article, section 33 of the PDPO — the restriction on transferring personal data out of Hong Kong — is not in force. That does not mean transfers are unrestricted. You remain responsible for security, purpose limitation, and openness. Treat an overseas API, including generative AI, as cross-border processing, and consider the PCPD’s recommended contractual clauses. Verify the latest text before you cite it.

Not in force is not no duty

Section 33 not being in force only means the dedicated transfer restriction has not started. The six data-protection principles still apply. You should be able to say who processes the data, for what, and how it is protected.

An overseas model is a transfer

Pasting client data into an overseas chat tool, or calling an overseas API, moves data out of Hong Kong. Contracts should limit purpose, onward transfer, security, deletion, and incident notice. The PCPD has published recommended clauses — check the year and version before you adopt them.

What an SME can do

List which fields leave Hong Kong. Keep highly sensitive fields in an enterprise account, private cloud, or on-prem system. Use public tools only for low-sensitivity or already public content.

Questions

Is section 33 in force?
As of this article, no. Do not tell clients that it is. Recheck the Gazette and the PCPD.
Staff in Hong Kong, servers abroad — is that a transfer?
If the data is stored or processed outside Hong Kong, treat it as a cross-border transfer and cover it with contract and access control.

This article is general information, not legal advice. PCPD guidance changes — check the latest version before you rely on it.

Want a first look at whether one real workflow touches personal data? Book a 1-hour business diagnosis.

Book a 1-hour diagnosis